SailPoint IdentityIQ and PM Cloud

This document provides the steps required to configure the integration between SailPoint IdentityIQ and Privilege Management Cloud for Windows and Mac.

Create the IdentityIQ Service Account in PM Cloud

Create an API account for IdentityIQ for PM Cloud integration.

  1. Log on to the PM Cloud web console as an Administrator.
  2. Go to Configuration, and then API Settings.
  3. Create an API account for IdentityIQ.

 

Configure SCIM Application in IdentityIQ for PM Cloud

You must log on to IdentityIQ using administrator credentials.

 

Add application in IdentityIQ for PM Cloud integration.

  1. Go to Applications, and then Application Definition.
  2. Click the Add New Application button.

 

In IdentityIQ, add application details for a PM Cloud integration.

  1. From the Application Type menu, select SCIM 2.0. Provide a name for the application.

 

Application configuration settings in IdentityIQ for PM Cloud integration.

  1. On the Configuration tab, provide the base URL and token URL. Select Client Credentials for Grant type. Enter the client Id and secret for the svc_iiq API account.

If the instance URL is https://pmc01.acme.somedomain.net then the API URLs are based on https://pmc01-services.acme.somedomain.com.

 

  1. Try testing the connection at this point.

Account attributes discovered in IdentityIQ setup with PM Cloud integration

  1. Go to the Schema tab.
  2. Click Discover Schema Attributes for Object Type: account.
  3. The attributes discovered for account are shown.

 

  1. Click Provisioning Policies.
  2. Click Add Policy, and then click Create Policy Form.

Add section in IdentityIQ for PM Cloud for integration.

  1. Click Add Section, then + on the new Section and Add Field. The first field is userName which maps to email address. Click Apply.

    The script format: return identity.getAttribute("email");

 

Set attribute givenName in IdentityIQ for PM Cloud integration.

  1. Set the attribute name.givenName. Click Apply.

 

Set attribute familyName in IdentityIQ for PM Cloud integration.

  1. Set the attribute name.familyName. Click Apply.

 

Set attribute email in IdentityIQ for PM Cloud integration.

  1. Set the attribute email. Click Apply.

 

Set attribute displayName in IdentityIQ for PM Cloud integration.

  1. Set the attribute displayName. Click Apply.

 

Settings for the active attribute in IdentityIQ for PM Cloud integration.

  1. Set the attribute active. Click Apply.

 

Set the locale attribute in IdentityIQ for PM Cloud integration.

  1. Set the attribute locale to static, and Value to en-US or en-GB. This can be mapped to an Identity attribute, if available.

 

Set the timezone attribute in IdentityIQ for PM Cloud integration.

  1. Set the attribute timezone to static value. This can be mapped to an Identity attribute, if available.

 

  1. Provide a form name and description, and then save the form. Don’t forget to save the application.
  2. Edit the application again, and go to Correlation.
  3. Create a correlation rule. Save the application.

Account Aggregation in SailPoint IdentityIQ for PM Cloud integration

  1. Create the aggregation task for PM Cloud. Navigate to Setup, then Tasks.
  2. Click the New Task menu, then select Account Aggregation.

 

Create aggregate task in IdentityIQ for PM Cloud integration

  1. Configure the task to scan PM Cloud. Scroll to the bottom of the page and click Save and Execute.
  2. Confirm the Task result is Success.

 

  1. Go back to the application and select the Accounts tab.

In IdentityIQ, discovered or aggregated accounts together with roles.

  1. Review the discovered or aggregated accounts together with roles.

 

Role entitlement example in IdentityIQ for PM Cloud integration

  1. Go to Applications, then Entitlement Catalog. Click Add New Entitlement button. The screen capture shows an example for role entitlement.

 

In IdentityIQ, the requestable roles for a PM Cloud integration.

  1. The Entitlement Catalog with the requestable roles for PM Cloud.

 

  1. Repeat the process for the following roles: Group Viewer, Policy Editor, Policy Viewer, Policy Assigner, Analytics, and Administrator.

Only roles are requestable. Entitlements are read-only in the current RBAC model. This will eventually change.

  1. Select a user that does not yet have access to PM Cloud from the menu in the upper left corner. Select Manage Access, and then Manage User Access.

Select users in IdentityIQ in a PM Cloud integration.

  1. Select a test user on the Manage User Access. Click Next.

 

Select a role in IdentityIQ when adding a user.

  1. Select a role under the PM Cloud Application. Click Next.

 

  1. Click Submit.
  2. The request should be in Verifying mode.

New user details in PM Cloud for IdentityIQ integration.

  1. Confirm the new user is added in PM Cloud.

 

The Application Accounts tab in IdentityIQ in a PM Cloud integration.

  1. Go to the Application Accounts tab and view the user application account and roles.